Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-40347

Опубликовано: 10 сент. 2021
Источник: debian
EPSS Низкий

Описание

An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
postoriusfixed1.3.5-1package

Примечания

  • https://gitlab.com/mailman/postorius/-/commit/3d880c56b58bc26b32eac0799407d74b64b7474b

  • https://phabricator.wikimedia.org/T289798

EPSS

Процентиль: 44%
0.00213
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 4 лет назад

An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.

CVSS3: 5.4
nvd
больше 4 лет назад

An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.

CVSS3: 5.4
github
больше 3 лет назад

GNU Mailman Postorius Access Control Issues

EPSS

Процентиль: 44%
0.00213
Низкий